SQL injection vulnerability in Datenbank MOD 2.7 and earlier for Woltlab Burning Board allows remote attackers to execute arbitrary SQL commands via the fileid parameter to (1) info_db.php or (2) database.php.
| Software | From | Fixed in |
|---|---|---|
| woltlab / burning_board | 2.4 | 2.4.x |
| woltlab / burning_board | 2.7 | 2.7.x |
| woltlab / burning_board | 1.1.1 | 1.1.1.x |
| woltlab / burning_board | 2.0_beta_4 | 2.0_beta_4.x |
| woltlab / burning_board | 2.2.2 | 2.2.2.x |
| woltlab / burning_board | 2.3.3 | 2.3.3.x |
| woltlab / burning_board | 2.3.1 | 2.3.1.x |
| datenbank_module / datenbank_module | - | 2.7.x |
| woltlab / burning_board | 2.0_beta_3 | 2.0_beta_3.x |
| woltlab / burning_board | 2.5 | 2.5.x |
| woltlab / burning_board | 2.6 | 2.6.x |
| woltlab / burning_board | 2.0_rc1 | 2.0_rc1.x |
| woltlab / burning_board | 2.0_beta_5 | 2.0_beta_5.x |
| woltlab / burning_board | 2.0_rc2 | 2.0_rc2.x |